Getting Data In

How can I get data coming from my Netflow (Flow Export) appliance into Splunk Enterprise

abdulhasnath
New Member

Hi,

Can someone direct me on what app I need to install to get data coming from my Netflow (Flow Export) appliance into Splunk Enterprise?

I have installed a forwarder and set the deployment/receiver server address to the address of where Splunk Enterprise is installed.
I have followed the Splunk Stream guide, and installed this app. Is this the right way?

Many thanks

0 Karma

richgalloway
SplunkTrust
SplunkTrust

In addition to pointing the forwarder at Splunk Enterprise, you must also tell Splunk Enterprise to accept data from the forwarder.
Go to Settings->Forwarding and receiving and click "Add new" under Receiving. Enter the port number to listen on (usually 9997) and click Save.

---
If this reply helps you, Karma would be appreciated.
0 Karma

abdulhasnath
New Member

Thanks for your answer. I have installed the forwarder + Splunk Enterprise on a server we have. How do I configure it to receive information from my NetFlow appliance, or is it just the case of me sending this information to the IP address + port number of the server that forwarder sits on from my appliance? If so, how do I then view this information on Splunk Enterprise? Sorry for all the questions, this is something new to us.

0 Karma

abdulhasnath
New Member

Also is it possible to add a 'pcap' file and view it in Splunk through dashboards? I've uploaded it via Settings>Data input but cannot see anything, I have also installed Splunk for PCAP files but no success?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Event Series: Splunk Observability Metrics Cost Optimization

Balancing Scale and Spend: Gaining Control Over High-Volume Metrics in Splunk Observability Cloud As ...

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...